Description
Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an administrator's dashboard session when the associated entry was viewed, or in the browser of any visitor to a page using an Express Entry List block with association columns, allowing actions to be performed with that user's privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks v01demort for reporting.
Published: 2026-09-15
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross‑site scripting. An unauthenticated attacker could submit a payload through a public Express Form, and the malicious code subsequently executes in an administrator's dashboard session when that entry is viewed, or in any visitor's browser, allowing actions to be performed with the user's privileges.

Affected Systems

Concrete CMS installations that are running any version earlier than 9.5.3 are affected. The vulnerability was identified in the official release announcements for Concrete CMS 9.5.3, which contains the remediation. The product name is Concrete CMS.

Risk and Exploitability

The flaw has a CVSS v4.0 score of 2.3, indicating low impact severity. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw by submitting a crafted payload through an Express form that is publicly accessible. Because the data is stored, the malicious code executes each time the associated entry is rendered, offering potential for session hijacking, defacement, or user‑agent phishing. The lack of credentials reduces the barrier to entry, but the actual damage depends on who views the content – an administrator or a passive visitor.

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Concrete CMS installation to version 9.5.3 or later, which includes escaping of Express entry labels.
  • If the upgrade cannot be performed immediately, ensure that all Express entry labels are sanitized or escaped before rendering to prevent script execution.
  • Implement a web‑application firewall or content‑security‑policy headers to mitigate stored XSS exposure in legacy installations.

Generated by OpenCVE AI on September 20, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Concretecms
Concretecms concrete Cms
Vendors & Products Concretecms
Concretecms concrete Cms

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an administrator's dashboard session when the associated entry was viewed, or in the browser of any visitor to a page using an Express Entry List block with association columns, allowing actions to be performed with that user's privileges. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks v01demort for reporting.
Title Concrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectors
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Concretecms Concrete Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: ConcreteCMS

Published:

Updated: 2026-09-15T19:25:54.113Z

Reserved: 2026-07-30T18:04:50.763Z

Link: CVE-2026-68534

cve-icon Vulnrichment

Updated: 2026-09-15T19:25:50.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:37.303

Modified: 2026-09-16T19:16:15.097

Link: CVE-2026-68534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')